ZeroFox Intelligence Flash Report - Active Exploitation of Juniper RCE Vulnerabilities
|by Alpha Team

ZeroFox Intelligence Flash Report - Active Exploitation of Juniper RCE Vulnerabilities
Product Serial: F-2023-11-17a
TLP:CLEAR
In this Intelligence Flash Report, ZeroFox researchers discuss the CISA addition of five Juniper Junos operating system vulnerabilities to its Known Exploited Vulnerabilities Catalog.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here.
Key Findings
- On November 13, 2023, the Cybersecurity and Infrastructure Security Agency (CISA) added five Juniper Junos operating system (OS) vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation.
- A recent Proof-of-Concept (PoC) for four of the vulnerabilities demonstrated how an unauthenticated, network-based threat actor may be able to remotely execute malware on unpatched assets by chaining exploitation of these vulnerabilities.
- Threat actors' increased adoption of the vulnerability chaining technique poses a complex cyber threat to organizations with unpatched internet-facing assets.
- Based on the availability of PoC exploits, which lower the barriers to entry for exploiting these vulnerabilities, ZeroFox assesses these vulnerabilities to be critical as a collective because threat actors are likely to exploit them on unpatched assets in the long term, potentially leading to widespread exploitation.
- ZeroFox anticipates that threat actors are very likely to create their own customized PoC exploits and sell them on darknet forums.
Tags: tlp:clear, vulnerability/exploit